Назад
Company hidden
2 дня назад

Governance, Risk & Compliance (GRC) Manager (SaaS)

140 000 - 165 000CAD
Формат работы
remote (только Canada)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Governance, Risk & Compliance (GRC) Manager (SaaS): Leading and maturing Fullscript’s security compliance program across SOC 2 Type II, PCI DSS, and HITRUST with an accent on audit readiness, risk management, and scalable control operations. Focus on leading external audits, coordinating remediation across technical and business teams, and managing a team of two GRC professionals.

Location: Remote, with locations listed in Ottawa, Toronto, or Calgary, Canada

Salary: CAD 140,000–165,000 per year

Company

hirify.global is a healthcare technology company helping people improve their health through access to practitioner-directed products.

What you will do

  • Own and evolve the Governance, Risk & Compliance program across SOC 2 Type II, PCI DSS, and HITRUST.
  • Lead external audits, including planning, evidence collection, auditor coordination, remediation, and certification.
  • Manage internal control assessments, readiness activities, risk registers, and remediation tracking.
  • Develop policies, standards, procedures, control documentation, reporting, and compliance dashboards.
  • Partner with Security, Engineering, Infrastructure, Privacy, Legal, Product, and IT to operationalize security controls.
  • Lead, coach, and develop a team of two GRC professionals while remaining hands-on in execution.

Requirements

  • 7+ years of experience in Governance, Risk & Compliance, Information Security, IT Audit, or Security Compliance.
  • People management experience leading small, high-performing teams.
  • Hands-on ownership of enterprise compliance programs in SaaS or healthcare technology organizations.
  • Experience leading external audits for SOC 2 Type II, PCI DSS, and HITRUST.
  • Familiarity with HIPAA and security frameworks including NIST CSF, CIS Controls, ISO 27001, and HITRUST.
  • Strong project management, organizational, written communication, and verbal communication skills.

Nice to have

  • Healthcare or health technology experience.
  • Experience with Vanta, Drata, OneTrust, or similar GRC platforms.
  • Certifications such as CISSP, CISA, CRISC, CISM, HITRUST CCSFP, PCI ISA/QSA, or ISO 27001 Lead Auditor.
  • Experience supporting customer security reviews and enterprise sales due diligence.

Culture & Benefits

  • Flexible remote, in-office, or hybrid work through the Wherever You Work Well philosophy.
  • Generous paid time off and flexible benefits.
  • RRSP matching program and workplace wellness program.
  • Training budget and company-wide learning initiatives.
  • Discounts on hirify.global products.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →